SPF record checker

Updated

Enter a domain to see its SPF record, how many of the 10 permitted DNS lookups it uses, and what to fix.

Looks up public DNS only. Nothing you enter is stored.

What the checker tests

  • Exactly one record starting with v=spf1
  • The total DNS lookups from include, a, mx, ptr, exists and redirect, following nested includes (limit 10)
  • Includes that point at a domain with no SPF record, which makes the whole check fail
  • The ending all mechanism: +all is dangerous, ?all is neutral, ~all and -all are the normal choices
  • Use of the deprecated ptr mechanism

It does not check whether a particular IP address would pass. It reads the record and the includes.

Fixing the common problems

Too many lookups. Remove includes for services you no longer use. Where possible replace an include: with explicit ip4: or ip6: ranges, which cost no lookups. Avoid flattening by hand unless you will keep it updated, because providers change their IPs.

Two SPF records. Merge them. If one says v=spf1 include:_spf.google.com ~all and another says v=spf1 include:amazonses.com ~all, publish one record: v=spf1 include:_spf.google.com include:amazonses.com ~all.

Missing record when sending with Inboxili. The Deliverability Center shows the SPF value to publish for your domain. If you already have an SPF record, add the include to it instead of creating a second one.

Background reading: SPF, DKIM and DMARC explained.

Frequently asked questions

Why does SPF fail with more than 10 lookups?
The SPF specification caps the number of DNS-querying terms (include, a, mx, ptr, exists, redirect) at 10 per evaluation, including those inside nested includes. Past that limit receivers return a permanent error.
Can I have more than one SPF record?
No. Publish one TXT record starting with v=spf1 and combine all senders into it.
What is the difference between ~all and -all?
~all is a soft fail: unlisted senders are marked suspicious. -all is a hard fail. Many senders start with ~all and move to -all once they are sure every legitimate sender is listed.

Need reliable email delivery? Try Inboxili

Create a workspace, verify a domain, and make your first API call.

Related